5 ms·
So gain access to a machine that can ask microsoft intune to eviscerate the company, ask it to do so, done. Bit of a shame all the machines had that installed r
by JonChesterfield 7mo ago
So gain access to a machine that can ask microsoft intune to eviscerate the company, ask it to do so, done. Bit of a shame all the machines had that installed really. Reminds me of crowdstrike.
- shiroiuma 7mo agoThe company should have known better than to trust their IT infrastructure to Microslop. This is their own fault.
- Xylakant 7mo agoMy 95% bet is that the attacker just gained access to an account with suitable privileges and then went on to use existing automation. The fact that it’s intune is largely irrelevant - I’m not aware of any safeguards that any provider would implemen. So the options here are MDM or no MDM and that’s a hard choice. No MDM means that you have to trust all people to get things as basic as FDE or a sane password policy right. No option to wipe or lock lost devices. No option to unlock devices where people forgot their password. Using an MDM means having a privileged attack vector into all machines.
- neo_doom 7mo agoNo MDM just isn’t an option for most enterprises but ideally the keys to the kingdom are properly secured.
- mulmen 7mo agoHow does that look exactly? Someone has to be able to use MDM to manage devices or there’s no point in having it. This scenario is firmly in rubber hose/crescent wrench cryptanalysis territory. Can updates have delays with approval gates built in? Does MDM need a break glass capability?
- heraldgeezer 7mo ago"Principle of least privilege" as MS calls it. Do not use global admin or admin account as daily driver for one. Dont save it in browser etc either. Limit roles, even within the application, here Intune. Office 365 also has conditional access and many policy leavers to tweak, many cases of people locking themselves OUT of 365. So the gates work but you need to configure them. "Break glass" global admin accounts now also require MFA. https://learn.microsoft.com/en-us/entra/identity/authentication/concept-mandatory-multifactor-authentication?tabs=dotnet https://learn.microsoft.com/en-us/entra/identity/authenticat...
- mulmen 7mo agoOk and who has access to the global admin and how resistant are they to Iranian operatives?
- heraldgeezer 7mo agoWhat are you asking? For Stryker specifically? We don't and probably won't know details. For companies in general? Background checks, security clearance etc are done if the company determines this necessary and are willing to pay for the process and higher salary.
- heraldgeezer 7mo ago[flagged]
- JonChesterfield 7mo agoWell, all the machines in the current outfit are Linux as far as I know. Services are self hosted. Seems to be fine, teams et al run adequately in a browser for talking to people on other stacks. Previous place had a corporate controlled windows laptop that made a very poor thin client for accessing dev machines. One before that had a somewhat centrally managed macbook that made a very poor thin client for accessing dev machines. You don't have to soul bond to Microsoft to get things done.
- Ekaros 7mo agoI don't see how Linux would prevent anything if company wants similar controls on their machines. Like tracking update status, forcing updates when needed, potentially wiping entire device when stolen and so on. Fault really is not the OS but the control corporate wants over their devices. And it does make some sense.
- pjc50 7mo agoIndeed. You'd expect a corporate IT system to be able to ssh as root into all their devices. And the cloud is even worse: if you get hold of the right IAM role, you can simply delete everything! That does usually get locked behind proper 2FA, but it's not impossible to phish even experienced admins once in a while.
- namibj 7mo agoCompare to the Facebook global BGP breakage and the amount of hands-on authorization that needed to happen to recover. And no, there are plenty systems you don't want to have root ssh on. Mainframes require 4-eyes administration to do more nuanced "root" things than picking up a sledgehammer and physically smashing drives.
- 7mo ago
- heraldgeezer 7mo ago[flagged]
- JonChesterfield 7mo agoAn alternative is people install the software they choose to on the machines they're using. Optionally write a list of suggested programs down somewhere. In that world, there is no central IT team pushing changes to machines and arguing with developers about whether they really need to be able to run a debugger. I don't know how to keep windows machines alive. It's probably harder.
- vntok 7mo agoI, for one, don't really want employees to install video games, porn cam clients, torrenting apps, shady vpn clients, crypto miners, remote access tools, dns "optimizers" and more generally viruses on their work computers.
- pjc50 7mo agoIt's annoying, but it's also grossly irresponsible to let dev machines get compromised. Regardless of which OS they are running.
- heraldgeezer 7mo agoThat is all well and good but how do you: - Ensure the machines are up-to-date and users are not just indefinitely postponing OS updates? - Same as above but with programs/software - How do you ensure correct settings configuration in terms of security? Say default browser, extensions, program access etc? - Re-image or reinstall the OS when there are issues or PC handover to another employee? Manually with a USB stick? This kind of control exists and is needed for Linux and MacOS too. RMM is not a Windows only thing... The critics here see Intune but what if they used another RMM and they compromised another cloud RMM account? Same issue. Also, here there is no "arguing". They order the software from our portal and it gets pushed into Company Portal via Intune... Write down a list you say... idk what to say. You have only worked for small startups I gather? Nothing wrong with that but please recognize that these types of limits and programs are not deployed for fun or to ruin your day.
- GorbachevyChase 7mo agoMicrosoft keeps disappointing and chief technology officers keep paying them. Wasn’t Elon Musk supposed to prove you could vibe code their entire product line? What happened to all that?
- nclin_ 7mo ago[dead]